Sr. Security Engineer, Product Security

4 Months ago • 8 Years + • Cyber Security

Job Summary

Job Description

The Sr. Security Engineer, Product Security will provide technical leadership to a team securing Xerox's digital platforms. Responsibilities include assessing applications for vulnerabilities, implementing secure SDLC processes, performing secure code reviews, developing security automation tools, defining security requirements, conducting security training, reporting on security metrics, researching industry trends, and acting as a security evangelist. This role requires strong application security expertise and collaboration skills.
Must have:
  • Assess applications for vulnerabilities
  • Implement secure SDLC processes
  • Secure code reviews/static analysis
  • Develop security automation tools
  • Threat modelling, security design reviews
  • Security training for development teams
  • Report on product security metrics
  • 8+ years cybersecurity experience, 5+ in product security
Good to have:
  • Java, .Net, C#, C, C++ experience
  • Prior software development experience

Job Details

About the job


About Xerox Holdings Corporation

For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power today’s workforce. From the office to industrial environments, our differentiated business solutions and financial services are designed to make every day work better for clients — no matter where that work is being done. Today, Xerox scientists and engineers are continuing our legacy of innovation with disruptive technologies in digital transformation, augmented reality, robotic process automation, additive manufacturing, Industrial Internet of Things and cleantech. Learn more at www.xerox.com and explore our commitment to diversity and inclusion.

Summary:

This position is part of the Xerox Cyber Security team that is responsible for driving security of Xerox digital platforms. The qualified candidate will provide technical leadership to a multidisciplinary product security team that is responsible for securing enterprise systems, applications, and products across a broad spectrum of technologies. The candidate must demonstrate a passion for application security and lead by example that fosters continued growth and technical expertise within the team.

Responsibilities include, but are not limited to:

  • Assess applications and products for security vulnerabilities and design flaws
  • Implement secure SDLC processes through effective collaboration
  • Manual and Automated Secure Code Review
  • Development of security automation tools
  • Develop and maintain secure coding practices and security engineering standards for the development team
  • Perform threat modelling, security design reviews of application or products and define security requirements as part of SDLC process
  • Security training for internal development teams
  • Track and report on product security metrics and communicate the security posture of products to stakeholders.
  • Research, analyze and report on security industry trends and products
  • Serve as a security evangelist for executive management and business stakeholders.

Knowledge and Skills Required:

  • Strong understanding of common vulnerabilities, attack vectors and corresponding mitigation techniques
  • Experience in performing secure code reviews/reviewing results of static analysis tools
  • In-depth understanding of secure coding practices and secure development life cycle principles.
  • Good understanding of SSDLC as well as development and integration of tools used as part of CI/CD process
  • Have good understanding of authentication and authorization standards and protocols (SAML, Oauth, LDAP etc.)
  • Strong exposure to popular application security standards including OWASP TOP 10, SANS TOP 25 etc.
  • Proficiency with at least one of the following programming languages desired: Java, .Net, C#, C, C++
  • Prior software development experience is a plus.
  • Strong interpersonal skills as well as excellent written and verbal communication skills
  • Uncompromising personal and professional integrity and ethics

Education and Experience Required:

  • B.S in computer science, information systems, engineering or related field.
  • Advanced degree preferred, i.e. MBA or MS
  • Over 8 years of experience in cybersecurity, with at least 5 years in product security
  • One or more Industry-standard security certifications (such as OSCP, OSWE, CWEE, OSED)

Similar Jobs

Meta - Software Engineer, Machine Learning

Meta

Singapore (On-Site)
4 Months ago
Next Level Business Services - Angular JS Developer

Next Level Business Services

Milwaukee, Wisconsin, United States (On-Site)
5 Months ago
Logitech - Sr. System Engineer (Atlassian Platforms)

Logitech

Cork, County Cork, Ireland (Hybrid)
5 Months ago
Nagarro - Associate Staff Engineer

Nagarro

Philippines (Remote)
5 Months ago
ByteDance - Mobile Software Engineer Graduate (Global E-commerce-US) - 2025 Start (BS/MS)

ByteDance

San Jose, California, United States (On-Site)
5 Months ago
PwC - Cyber Security Associate

PwC

Bangkok, Bangkok, Thailand (On-Site)
5 Months ago
The Walt Disney Company - Investigations Analytics Manager

The Walt Disney Company

Glendale, California, United States (On-Site)
1 Week ago
SmileGate - Security Threat and Incident Analysis

SmileGate

Seongnam-si, Gyeonggi-do, South Korea (On-Site)
6 Days ago
NVIDIA - Network Security Research Architect

NVIDIA

(Remote)
1 Week ago
PwC - Senior Associate, Infrastructure and Operations, Cybersecurity

PwC

Vaughan, Ontario, Canada (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Google - Early Career Software Engineer, People with Disabilities

Google

State Of Minas Gerais, Brazil (On-Site)
3 Months ago
Microsoft - Member of Technical Staff - Product Engineer, Evaluation Tooling

Microsoft

Mountain View, California, United States (Hybrid)
1 Week ago
Scopely - Senior Software Engineer (PHP)

Scopely

Bengaluru, Karnataka, India (Hybrid)
2 Months ago
Zeta - Senior Software Development Engineer _ Backend

Zeta

Bengaluru, Karnataka, India (On-Site)
5 Months ago
Netflix - Software Engineer L4 - Finance and Tax Technology

Netflix

Warsaw, Masovian Voivodeship, Poland (Hybrid)
2 Months ago
Warner Bros Games - Staff Software Engineer - MSC Rights Team

Warner Bros Games

Bengaluru, Karnataka, India (Hybrid)
1 Month ago
Salesforce - 2025 PhD Intern - AI Research, Singapore

Salesforce

Singapore, Singapore (On-Site)
5 Months ago
Niantic - Security Engineer, Production

Niantic

Zürich, Zurich, Switzerland (Hybrid)
6 Days ago
ByteDance - Software Development Engineer Graduate (Network Monitoring & Alerts) - 2025 Start (PhD)

ByteDance

Seattle, Washington, United States (On-Site)
5 Months ago
Rackspace Technology - Principal Java Engineer (GCP)

Rackspace Technology

United States (Remote)
1 Week ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Alpha Sense - Technical Program Manager

Alpha Sense

Pune, Maharashtra, India (On-Site)
3 Months ago
PwC - IN_Manager_CPI_Enterprise Apps SAP_Advisory_Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
4 Months ago
PwC - Specialist 3

PwC

Gurugram, Haryana, India (On-Site)
5 Months ago
PwC - IN- Manager_SAP ABAP_Enterprise Apps SAP_Advisory _PAN India

PwC

Pune, Maharashtra, India (On-Site)
4 Months ago
Logitech - Audio DSP engineer

Logitech

Chennai, Tamil Nadu, India (On-Site)
6 Months ago
CropBytes - Product Manager

CropBytes

India (On-Site)
1 Year ago
PwC - IN_Director_SAP PP QM_Enterprise apps SAP_Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
6 Months ago
Juego Studios - Senior Unity Developer

Juego Studios

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Eleven Labs - Senior Customer Success Manager - India

Eleven Labs

India (Remote)
3 Days ago
PwC - Senior Consultant

PwC

Mumbai, Maharashtra, India (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Senior Associate, Infrastructure and Operations, Cybersecurity

PwC

Vaughan, Ontario, Canada (On-Site)
2 Months ago
Trend Micro - Sr. Engineer

Trend Micro

Taipei City, Taiwan (On-Site)
6 Months ago
PhonePe - Product Security Engineer

PhonePe

Bengaluru, Karnataka, India (On-Site)
4 Months ago
ByteDance - Global Head of Solution Architect, SealSuite

ByteDance

Singapore (On-Site)
2 Months ago
PwC - IN_Senior Associate_Agile PM_Advisory Corporate_Advisory_Pune

PwC

Pune, Maharashtra, India (On-Site)
5 Months ago
Immutable - Application Security Engineer

Immutable

Sydney, New South Wales, Australia (Hybrid)
1 Month ago
LogicMonitor - Staff Penetration Testing Engineer

LogicMonitor

Pune, Maharashtra, India (Hybrid)
4 Months ago
ION - Network Security Engineer

ION

Castellazzo Bormida, Piedmont, Italy (Hybrid)
5 Months ago
PwC - Cyber Governance Risk & Compliance| Manager | Cyber Security | Technology Consulting

PwC

Dublin, County Dublin, Ireland (On-Site)
6 Months ago
Assystems - SOC L1 Analyst

Assystems

Gurugram, Haryana, India (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded